Options

Computer Mess - Need Help

My computer is a complete mess, here is my HTJ

Logfile of HijackThis v1.98.2
Scan saved at 10:00:32 PM, on 9/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\sysupd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\James Betker\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.roadrunnerrecords.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://web.lghsgowxrog.org/4ZGYN/2naIGTbIYZn6xuzrna4gcwrntYMdGKNW6Qv5rZ92CWSSb9UScimQN8BsM8.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mydailyhoroscope.net/mdh/launch1.aspx?API=3|13039|1.0.1.0&TZ=5&LC=1&
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: Ðj5Ðj5hb5hb5˜5˜5*5*5¨5¨5°5°5¸5¸5À5À5È5È5Ð5Ð5Ø5Ø5à5à5è5è5ð5ð5ø5ø5 ˆ555˜5˜5*5*5¨5¨5°5°5¸5¸5À5À5È5È5Ð5Ð5Ø5Ø5à5à5è5è5ð5ð5ø5ø5
O1 - Hosts: 5˜5˜5*5*5¨5¨5°5°5¸5¸5À5À5È5È5Ð5Ð5Ø5Ø5à5à5è5è5ð5ð5ø5ø5
O1 - Hosts: (j0ˆ0
O1 - Hosts: (ja(jaaaèÿaèÿa*a*a_aàra°a°a¸a¸aÀaÀaÈaÈaè{aˆ'äØaØaàaàaèaèaðaðaøaøa ˆaaa˜a˜a*a*a¨a¨a°a°a¸a¸aÀaÀaÈaÈaÐaÐaØaØaàaàaèaèaðaðaøaøa
O1 - Hosts: a˜a˜a*a*a¨a¨a°a°a¸a¸aÀaÀaÈaÈaÐaÐaØaØaàaàaèaèaðaðaøaøa
O1 - Hosts: Ðj Ðj hb ˆ èÿ èÿ * * 7 7 ° ° ¸ ¸ À À È È ˆ $¾ Ø Ø à à è è ð ð ø ø ˆ   ˜ ˜ * * ¨ ¨ x(¾ x(¾ ¸ ¸ À À È È Ð Ð Ø Ø à à è è ð ð ø ø
O1 - Hosts:  ˜ ˜ * * ¨ ¨ ° ° ¸ ¸ À À È È Ð Ð Ø Ø à à è è ð ð ø ø
O1 - Hosts: Øl9Øl999˜9˜9¨e9¨e9xr9xr9˜y9˜y9¸9¸9À9À9¸ÿ9hû9¨|9xj¬ Ø9Ø9à9à9è9è9ð9ð9ø9ø9 ˆ999˜9˜9*9*9¨9¨9°9°9¸9¸9À9À9È9È9Ð9Ð9Ø9Ø9à9à9è9è9ð9ð9ø9ø9
O1 - Hosts: 9˜9˜9*9*9¨9¨9°9°9¸9¸9À9À9È9È9Ð9Ð9Ø9Ø9à9à9è9è9ð9ð9ø9ø9
O1 - Hosts: www.look2me1.com
O1 - Hosts: *@=x= www.look2me2.com
O1 - Hosts: ¸b=x= www.look2me3.com
O1 - Hosts: Ðd=x= www.look2me4.com
O1 - Hosts: www.look2me5.com
O1 - Hosts: k=k===˜=˜=*=*=¨=¨=°=°=¸=¸=À=À=È=È=Ð=Ð=Ø=Ø=à=à=s=s=ð=ð=ø=ø= ˆ===˜=˜=*=*=¨=¨=°=°=¸=¸=À=À=È=È=Ð=Ð=Ø=Ø=à=à=è=è=ð=ð=ø=ø=
O1 - Hosts: =˜=˜=*=*=¨=¨=°=°=¸=¸=À=À=È=È=Ð=Ð=Ø=Ø=à=à=è=è=ð=ð=ø=ø=
O2 - BHO: (no name) - {5202968D-40B9-9255-03BA-FDD8E816C249} - C:\PROGRA~1\REGSMP~1\WinMapi.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: McAfee Privacy Service - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: JetBar Toolbar - {8E2FF476-C576-4637-9F73-5FFE2116CC12} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\JetBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [covqRkM5Q] iprml3.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EFAEF39-9A49-4615-B54A-597AAEC538E6} - http://download.jetbar.com/JetBar.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.aimphuck.com/Imbum_bw.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v5.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab


If anyone can help, I'll be GRATEFUL, thanks in advance.

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2004
    Well damn, I can't let a fellow bass player go on suffering like this....

    I hope you're a bass player and not a "boom"-bass-type ;)

    Either way, I'll help you :D

    Fix the following in HJT:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://web.lghsgowxrog.org/4ZGYN/2n...i mQN8BsM8.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mydailyhoroscope.net/mdh/launch1.aspx?API=3|13039|1.0.1.0&TZ=5&LC=1&
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: Ðj5Ðj5hb5hb5˜5˜5*5*5¨5¨5°5°5¸ 5¸5À5À5È5È5Ð5Ð5Ø5Ø5à5à5è5 è5ð5ð5ø5ø5 ˆ555˜5˜5*5*5¨5¨5°5°5¸5¸ 5À5À5È5È5Ð5Ð5Ø5Ø5à5à5è5è5 ð5ð5ø5ø5
    O1 - Hosts: 5˜5˜5*5*5¨5¨5°5°5¸5¸5À5À 5È5È5Ð5Ð5Ø5Ø5à5à5è5è5ð5ð5 ø5ø5
    O1 - Hosts: (j0ˆ0
    O1 - Hosts: (ja(jaaaèÿaèÿa*a*a_aàra°a°a¸ a¸aÀaÀaÈaÈaè{aˆ'äØaØaàaàaèa èaðaðaøaøa ˆaaa˜a˜a*a*a¨a¨a°a°a¸a¸ aÀaÀaÈaÈaÐaÐaØaØaàaàaèaèa ðaðaøaøa
    O1 - Hosts: a˜a˜a*a*a¨a¨a°a°a¸a¸aÀaÀ aÈaÈaÐaÐaØaØaàaàaèaèaðaða øaøa
    O1 - Hosts: Ðj Ðj hb ˆ èÿ èÿ * * 7 7 ° ° ¸ ¸ À À È È ˆ $¾ Ø Ø à à è è ð ð ø ø ˆ   ˜ ˜ * * ¨ ¨ x(¾ x(¾ ¸ ¸ À À È È Ð Ð Ø Ø à à è è ð ð ø ø
    O1 - Hosts:  ˜ ˜ * * ¨ ¨ ° ° ¸ ¸ À À È È Ð Ð Ø Ø à à è è ð ð ø ø
    O1 - Hosts: Øl9Øl999˜9˜9¨e9¨e9xr9xr9˜y9˜y9¸ 9¸9À9À9¸ÿ9hû9¨|9xj¬ Ø9Ø9à9à9è9è9ð9ð9ø9ø9 ˆ999˜9˜9*9*9¨9¨9°9°9¸9¸ 9À9À9È9È9Ð9Ð9Ø9Ø9à9à9è9è9 ð9ð9ø9ø9
    O1 - Hosts: 9˜9˜9*9*9¨9¨9°9°9¸9¸9À9À 9È9È9Ð9Ð9Ø9Ø9à9à9è9è9ð9ð9 ø9ø9
    O1 - Hosts: www.look2me1.com
    O1 - Hosts: *@=x= www.look2me2.com
    O1 - Hosts: ¸b=x= www.look2me3.com
    O1 - Hosts: Ðd=x= www.look2me4.com
    O1 - Hosts: www.look2me5.com
    O1 - Hosts: k=k===˜=˜=*=*=¨=¨=°=°=¸ =¸=À=À=È=È=Ð=Ð=Ø=Ø=à=à=s= s=ð=ð=ø=ø= ˆ===˜=˜=*=*=¨=¨=°=°=¸=¸ =À=À=È=È=Ð=Ð=Ø=Ø=à=à=è=è= ð=ð=ø=ø=
    O1 - Hosts: =˜=˜=*=*=¨=¨=°=°=¸=¸=À=À =È=È=Ð=Ð=Ø=Ø=à=à=è=è=ð=ð= ø=ø=
    O2 - BHO: (no name) - {5202968D-40B9-9255-03BA-FDD8E816C249} - C:\PROGRA~1\REGSMP~1\WinMapi.exe

    O3 - Toolbar: JetBar Toolbar - {8E2FF476-C576-4637-9F73-5FFE2116CC12} - C:\WINDOWS\Downloaded Program Files\CONFLICT.1\JetBar.dll

    O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [covqRkM5Q] iprml3.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    O16 - DPF: {8EFAEF39-9A49-4615-B54A-597AAEC538E6} - http://download.jetbar.com/JetBar.cab

    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.aimphuck.com/Imbum_bw.cab

    O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab

    Remove all those, then PULL THE PLUG on your computer - do not reboot properly!

    After you plug it back in, turn it on and post a new log :)
Sign In or Register to comment.